The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Inspect TPM readiness | Get-Tpm |
Select-Object TpmPresent, TpmReady, TpmEnabled, TpmActivated, RestartPending, LockedOut | View examples |
| Audit BitLocker volumes | Get-BitLockerVolume |
Select-Object MountPoint, VolumeType, VolumeStatus, ProtectionStatus, EncryptionMethod, EncryptionPercentage | View examples |
| Check status with manage-bde | manage-bde.exe -status C: | View examples |
| List protector metadata | (Get-BitLockerVolume -MountPoint $env:SystemDrive).KeyProtector |
Select-Object KeyProtectorId, KeyProtectorType | View examples |
| Resolve recovery protector ID | (Get-BitLockerVolume $env:SystemDrive).KeyProtector |
Where-Object KeyProtectorType -eq 'RecoveryPassword' |
Select-Object KeyProtectorId | View examples |
| Back up to Microsoft Entra ID | BackupToAAD-BitLockerKeyProtector -MountPoint `
$env:SystemDrive -KeyProtectorId `
'{RECOVERY-PROTECTOR-GUID}' | View examples |
| Back up to AD DS | Backup-BitLockerKeyProtector -MountPoint `
$env:SystemDrive -KeyProtectorId `
'{RECOVERY-PROTECTOR-GUID}' | View examples |
| Preview TPM enablement | Enable-BitLocker -MountPoint $env:SystemDrive `
-EncryptionMethod XtsAes256 -TpmProtector `
-UsedSpaceOnly -WhatIf | View examples |
| Preview adding recovery | Add-BitLockerKeyProtector -MountPoint $env:SystemDrive `
-RecoveryPasswordProtector -WhatIf | View examples |
| Preview one-reboot suspension | Suspend-BitLocker -MountPoint $env:SystemDrive `
-RebootCount 1 -WhatIf | View examples |
| Preview protection resume | Resume-BitLocker -MountPoint $env:SystemDrive -WhatIf | View examples |
| Verify protection resumed | Get-BitLockerVolume $env:SystemDrive |
Select-Object MountPoint, VolumeStatus, ProtectionStatus, LockStatus | View examples |
| Audit automatic unlock | Get-BitLockerVolume |
Select-Object MountPoint, VolumeType, AutoUnlockEnabled, ProtectionStatus | View examples |
| Preview disabling auto-unlock | Disable-BitLockerAutoUnlock -MountPoint 'D:' -WhatIf | View examples |
| Preview BitLocker decryption | Disable-BitLocker -MountPoint 'D:' -WhatIf | View examples |
| Read BitLocker events | Get-WinEvent -LogName `
'Microsoft-Windows-BitLocker/BitLocker Management' `
-MaxEvents 50 | View examples |
BitLocker encrypts volumes; a key protector controls how the volume encryption key is released, and a TPM can bind release to measured boot state. Encryption percentage alone does not prove that protection is active. Inventory volume status, protection status, TPM readiness, and protector types together. Before enabling, suspending, rotating, decrypting, or changing firmware, verify recovery information is securely escrowed away from the protected device and that authorized staff can retrieve it.
Step by step
Detailed examples
Establish TPM, volume, and protection state separately
Get-Tpm describes the local TPM, while Get-BitLockerVolume describes encryption and protectors. TpmPresent is not the same as TpmReady. Likewise, a FullyEncrypted volume can have ProtectionStatus Off if its protectors are suspended. Run read-only inventory first, from an elevated Windows PowerShell session when access is restricted, and record edition, join state, policy source, firmware plans, and restart requirements.
Get-Tpm | Select-Object TpmPresent, TpmReady, TpmEnabled, TpmActivated, RestartPending, LockedOut
Get-BitLockerVolume | Select-Object MountPoint, VolumeType, VolumeStatus, ProtectionStatus, EncryptionMethod, EncryptionPercentage, LockStatus
manage-bde.exe -status $env:SystemDrive Treat key protectors as access policy, not encryption algorithms
A volume encryption key can have multiple protectors, such as TPM, TPM plus PIN, recovery password, startup key, or certificate. Protector choice defines unlock and recovery paths; it does not change the volume's encryption method. Inventory IDs and types without printing RecoveryPassword. A recovery password grants access to all data on the volume, so never paste it into tickets, logs, shell history, screenshots, or shared transcripts.
$volume = Get-BitLockerVolume -MountPoint $env:SystemDrive
$volume | Select-Object MountPoint, EncryptionMethod, VolumeStatus, ProtectionStatus
$volume.KeyProtector | Select-Object KeyProtectorId, KeyProtectorType Prove recovery escrow before depending on a protector
Use the recovery-password protector GUID shown at recovery to locate the matching secret in the organization's approved vault. Microsoft recommends Microsoft Entra ID for Entra-joined devices and AD DS for domain-joined devices. Backup cmdlets require elevation, the appropriate join and permissions, and successful directory connectivity. Their success proves submission, not that the help desk can retrieve the key under incident conditions; test that process without exposing the password.
$recovery = (Get-BitLockerVolume $env:SystemDrive).KeyProtector | Where-Object KeyProtectorType -eq 'RecoveryPassword'
$recovery | Select-Object KeyProtectorId, KeyProtectorType
# After approval, pass the exact KeyProtectorId to BackupToAAD-BitLockerKeyProtector or Backup-BitLockerKeyProtector.
# Verify authorized recovery in the directory portal; do not print or log RecoveryPassword. Design policy and recovery before starting encryption
Enable-BitLocker can begin a long-running storage change and may require elevation, policy compliance, compatible hardware, free space, and a hardware test. UsedSpaceOnly is faster for new devices but is not a substitute for sanitizing previously used free space. Choose the encryption method through managed policy before deployment because changing it later requires full decryption and re-encryption. A TPM-only protector improves unattended startup but recovery must exist independently. Preview supported cmdlets with WhatIf and deploy through managed policy at scale.
$proposal = [pscustomobject]@{ MountPoint = $env:SystemDrive; Method = 'XtsAes256'; Protector = 'TPM'; Scope = 'Used space only' }
$proposal | Format-List
Enable-BitLocker -MountPoint $env:SystemDrive -EncryptionMethod XtsAes256 -TpmProtector -UsedSpaceOnly -WhatIf
Add-BitLockerKeyProtector -MountPoint $env:SystemDrive -RecoveryPasswordProtector -WhatIf Bound every suspension and verify the resume
Firmware and boot-component maintenance can trigger recovery when TPM measurements change. Suspension keeps data encrypted but makes the volume key available in the clear and disables normal boot-integrity validation, so it is a temporary security reduction. Use the smallest approved RebootCount, preserve recovery access, keep the device physically controlled, and verify ProtectionStatus after the final restart. A value of zero is indefinite and should be avoided unless an explicit resume is tightly controlled.
Get-BitLockerVolume $env:SystemDrive | Select-Object MountPoint, VolumeStatus, ProtectionStatus
Suspend-BitLocker -MountPoint $env:SystemDrive -RebootCount 1 -WhatIf
# Perform the approved change only after recovery escrow is verified.
Resume-BitLocker -MountPoint $env:SystemDrive -WhatIf
# After maintenance, rerun Get-BitLockerVolume and require ProtectionStatus On. Audit automatic unlock as an inherited trust decision
Automatic unlock stores information protected by the operating-system volume so an encrypted data volume opens after Windows unlocks. It improves availability but links the data volume's access to the OS volume and user context. Inventory each volume and confirm the behavior matches device ownership, removable-media policy, separation requirements, and recovery design. Changes normally require elevation; use WhatIf where supported.
Get-BitLockerVolume | Where-Object VolumeType -ne 'OperatingSystem' | Select-Object MountPoint, VolumeType, VolumeStatus, ProtectionStatus, AutoUnlockEnabled
Disable-BitLockerAutoUnlock -MountPoint 'D:' -WhatIf Distinguish suspension, locking, and full decryption
Suspension leaves sectors encrypted but weakens how the key is protected. Locking denies access to an encrypted data volume until an authorized unlock. Disable-BitLocker starts decrypting and ultimately removes BitLocker protection and protectors; it can take substantial time and increases exposure of data at rest. Confirm legal retention, device transfer, backup, power, maintenance, and monitoring requirements before approval, and never mistake pause or resume of conversion for protection suspend or resume.
$volume = Get-BitLockerVolume -MountPoint 'D:'
$volume | Select-Object MountPoint, VolumeStatus, ProtectionStatus, EncryptionPercentage, LockStatus
Disable-BitLocker -MountPoint 'D:' -WhatIf
# Decryption is disruptive and removes at-rest protection; execute only through an approved change. Collect evidence before changing TPM or protectors
Unexpected recovery can follow firmware, Secure Boot, boot configuration, hardware, docking, or policy changes. Capture the recovery-key ID displayed to the user, timestamps, BitLocker events, TPM state, recent changes, and protector metadata without collecting the recovery password. Do not clear the TPM as a generic fix: clearing resets it and can make TPM-protected credentials and keys unavailable. Identify the root cause, regain authorized access, and rotate a recovery password after use according to policy.
Get-Tpm | Select-Object TpmPresent, TpmReady, RestartPending, LockedOut
Get-BitLockerVolume $env:SystemDrive | Select-Object MountPoint, VolumeStatus, ProtectionStatus, EncryptionMethod
(Get-BitLockerVolume $env:SystemDrive).KeyProtector | Select-Object KeyProtectorId, KeyProtectorType
Get-WinEvent -LogName 'Microsoft-Windows-BitLocker/BitLocker Management' -MaxEvents 50 Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- MicrosoftBitLocker overviewlearn.microsoft.com
- MicrosoftBitLocker operations guidelearn.microsoft.com
- MicrosoftBitLocker recovery overviewlearn.microsoft.com
- MicrosoftBitLocker PowerShell modulelearn.microsoft.com
- MicrosoftTrusted Platform Module technology overviewlearn.microsoft.com
- MicrosoftGet-Tpmlearn.microsoft.com
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



